Yasm
Vendor:
First CVE: Apr 12, 2023 · Active for 3 years
17
Total CVEs
More Total CVEs than 93% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Yasm over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2023
3 years ago
Most Recent CVE
May 29, 2025
422 days ago
CVE Severity & Scoring
Yasm17 CVEs
88%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local16 (94.1%)
Network1 (5.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (94.1%)
High1 (5.9%)
Unknown0 (0.0%)
User Interaction
None1 (5.9%)
Unknown0 (0.0%)
Required16 (94.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None17 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31724HIGH yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c. | May 17, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-31725MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c. | May 17, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-31723MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function expand_mmac_params at /nasm/nasm-pp.c. | May 17, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-30402MEDIUM YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bu | Apr 25, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29583MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is | Apr 24, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29582MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is | Apr 24, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29579MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a | Apr 24, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29581MEDIUM yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if | Apr 12, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29580MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c. | Apr 12, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-49558MEDIUM An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component. | Jan 3, 2024 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Yasm
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2023-09-22 | 1 | 4.8 | 0.2% | 0 | 0 |
| 1.3.0.86.g9def | 5 | 5.5 | 0.4% | 0 | 0 |
| 1.3.0.78.g4dc8 | 1 | 5.5 | 0.3% | 0 | 0 |
| 1.3.0.55.g101bc | 8 | 5.8 | 0.3% | 0 | 0 |
| 1.3.0 | 2 | 4.4 | 0.4% | 0 | 0 |